OS Command Injection in GitHub repository jgraph/drawio prior to 21.5.0.
References
Link | Resource |
---|---|
https://github.com/jgraph/drawio/commit/8ec95cb03e0a80cf908a282522ac1651306db340 | Patch |
https://huntr.dev/bounties/4da96d20-78ac-462e-910c-a14db9062161 | Exploit Patch Permissions Required Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-07-27 15:15
Updated : 2023-08-03 13:33
NVD link : CVE-2023-3975
Mitre link : CVE-2023-3975
CVE.ORG link : CVE-2023-3975
JSON object : View
Products Affected
diagrams
- drawio
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')